Information disclosure in BIG-IP APM - CVE-2018-5544
Published: August 1, 2018 / Updated: August 2, 2018
BIG-IP APM
Detailed vulnerability description
The vulnerability allows a remote attacker to obtain potentially sensitive information.
The vulnerability exists due to insufficient input validation. A remote attacker can supply specially ctafted URI parameters when the system renders certain pages with a logon agent or a confirm box and obtain potentially sensitive configuration information, including partition and agent names.